Falhas do tipo CWE-668

235 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) através de canais inadequados: mensagens de erro verbosas, logs acessíveis, memória não limpa, headers HTTP desnecessários ou comportamentos diferenciados que vazam pistas. O risco está em que um atacante consegue reunir informações que facilitam outros ataques ou violam privacidade.

Exemplo

Um endpoint retorna 'Usuário não encontrado no banco de dados' em vez de apenas 'Credenciais inválidas', permitindo que alguém enumere usuários válidos; ou a aplicação deixa tokens JWT em cookies acessíveis ao JavaScript malicioso; ou logs de erro com stack traces são servidos publicamente.

Como mitigar

Sanitize mensagens de erro (respostas genéricas ao usuário final, logs detalhados apenas em backend seguro); revise headers HTTP (remova versões de software, X-Powered-By); nunca armazene segredos em código-fonte, variáveis de ambiente ou comentários; implemente rotação e expiração de tokens; configure logs com controle de acesso restrito e sem dados sensíveis em strings de debug.

CVE-2024-3019HIGHPcp: exposure of the redis server backend allows remote command execution via pmproxyEPSS 1.0%CVE-2022-29247LOWExposure of Resource to Wrong Sphere in ElectronEPSS 1.0%CVE-2022-0815MEDIUMMcAfee WebAdvisor - Extension Fingerprinting vulnerabilityEPSS 1.0%CVE-2023-34114HIGHExposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potenEPSS 1.0%CVE-2023-28433HIGHMinio Privilege Escalation on Windows via Path separator manipulationEPSS 1.0%CVE-2022-1467HIGHAVEVA InTouch Access Anywhere Exposure of Resource to Wrong SphereEPSS 1.0%CVE-2021-40496SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attackEPSS 0.9%CVE-2021-20999CRITICALWEIDMUELLER: Accidentally open network port in u-controls and IoT-GatewaysEPSS 0.9%CVE-2022-21718LOWRenderers can obtain access to random bluetooth device without permission in ElectronEPSS 0.9%CVE-2023-35696HIGHUnauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the deEPSS 0.9%CVE-2021-41140MEDIUMReactions leak for secure category topics and private messagesEPSS 0.9%CVE-2023-29208HIGHData leak through deleted documents EPSS 0.9%CVE-2025-32428CRITICALJupyter Remote Desktop Proxy makes TigerVNC accessible via the network and not just via a UNIX socket as intendedEPSS 0.9%CVE-2026-20160CRITICALCisco Smart Software Manager On-Prem Arbitrary Command Execution VulnerabilityEPSS 0.9%CVE-2022-32249Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gaEPSS 0.9%CVE-2020-26084MEDIUMCisco Edge Fog Fabric Resource Exposure VulnerabilityEPSS 0.9%CVE-2021-32788MEDIUMPost creator of a whisper post can be revealed to non-staff users in DiscourseEPSS 0.9%CVE-2022-20917MEDIUMA vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticEPSS 0.9%CVE-2026-44008CRITICALvm2: Snabox breakout via `neutralizeArraySpeciesBatch`EPSS 0.9%CVE-2020-26086MEDIUMCisco TelePresence Collaboration Endpoint Software Information Disclosure VulnerabilityEPSS 0.8%